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Administering F-PROT Professional 


The purpose of this Chapter is to provide specific instructions for administrator on 
managing F-PROT Professional for Windows and to give a general idea of how the 
program works. 


Administrator’s Tools 


1 The Administration Workstation 


When you choose the Network Administration Installation option during 
F-PROT Professional for Windows installation, you designate your own workstation 
as the administration workstation. This facilitates the two-way information flow 
between you and the users. However, any workstation can be used as the 
administration workstation simply by running F-PROT Professional on it in 
administration mode. It is better to avoid running in administration mode than one 
workstation at a time. 


The designation of a particular workstation can be viewed under General in the 
Administration Preference of the Preferences dialog box. The Administration 
Workstation check box will be selected or not, as appropriate. 


When the Administration Workstation check box is selected, F-PROT 
Professional asks for the administration password at every start-up. The request 
will be repeated three times. Any user who does not enter the correct password will 
be allowed access to the workstation, but only in user mode. 


The administration password can be changed in the Administration Preference 
dialog box by clicking Change. Before you type in the new password, the old 
password must be provided. 


The program can be switched from user mode to administration mode on any 
workstation by choosing Administration... from the File menu and entering the 
administration password in the displayed dialog box. 


2 The Communication Directory 


All the F-PROT network functions: updating, sending and receiving mail, and others, 
are handled through the shared communication directory. This directory is created 
during F-PROT installation, and its name may be in UNC format. Refer to Chapters 
11 and 12 for more discussion on communication directory and files. 


The communication directory name and path are shown in the Network 
Preference of the Preferencesdialog box. 


3 The Administration Menu 


The Administration menu is the administrator’s main tool for controlling F-PROT 
Professional for Windows. The menu contains commands needed to administer the 
system. 


Since the Administration menu is only visible when the program is run in 
Administration mode, it is hidden from normal users. To switch to Administration 
mode on some other workstation, simply click Administration... on the File menu 
and enter the administration password in the displayed dialog box. 


1.2 


5 
The Administration menu consists of the following commands: 


Command Function 


Distribute F-PROT Installations Modifies installation directory, creates installation 
directory for AUTOINST. 


Manage Bulletins... Opens the bulletin list. 
View User Messages... Opens the Read Messages dialog box. 
View User Reports... Opens the Read Reports dialog box. 


View User Infected Files... Displays the list of infected files sent from workstations. 


Distribute Selected Task Prompts for the task options, then makes task available in the 
network TASKS directory. 


Undistribute Selected Task Sends an Undistribute file to the shared disk. The 
corresponding task will be removed from user workstations. 


Send Update... Copies everything under the F-PROT Professional root 
directory (except what is under the LOCAL and SHARED 
directories) to UPDATE directory on the shared disk. 


Administrator Support Connects to the Administrator’s FAQ page on the F-PROT 


on the Web server. 


Distributing Tasks Through The Network 


Tasks can be created on the administration workstation and distributed to users via 
the network. F-PROT programs on local workstations will automatically add the 
distributed tasks to their task lists. Similarly, you can automatically remove a 
previously distributed task from all workstations connected to the network. 


1 Sending Tasks to Users 


Send a task to users by selecting it on the task list and clicking Distribute 
Selected Task on the Administration menu. 


In the subsequent dialog box, select Network as the distribution method. Click the 
check boxes below to select the desired options. 


If the Force report at first scan check box is selected, the local programs send 
the results of this task directly to administrator. 


If the Force immediate scan upon receiving task check box is selected, the 
task is executed immediately after being copied to local workstations. 


If the Protect task from modification check box is selected, the users cannot 
modify the task parameters. 


If the Disable aborting scan check box is selected, the users cannot terminate a 
scan during its execution. 


After you have chosen the desired options, click OK to copy the task file to the 
TASKS directory on the shared disk. When F-PROT programs on the local 
workstations notice that a new task has become available, they copy the task to 
the local hard disks and add it to their local task lists. 


A distributed task remains in the shared TASKS directory until removed by 
administrator. If a workstation is not connected to the network because it is 
switched off or not logged on to the network, or for other reasons, the task will be 
retrieved as soon as the contact with the server is regained. 


The task files distributed by the administrator have the extension .fpa, whereas 
user task files are designated .fpt. On the task lists of local workstations the 
distributed tasks are shown in a different color. 
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2 Removing a Previously Distributed Task 


Remove a task that you have previously distributed by selecting it on the task list 
and choosing Undistribute Selected Task from the Administration menu. 


The Undistribute Selected Task command sends the Undistribute file to the 
TASKS directory on the shared disk. The Undistribute file has the same name as the 
corresponding task file but is differentiated by the extension .del. When F-PROT on 
local workstations notices that an Undistribute file has appeared on the shared 
disk, the corresponding task is deleted from the local hard disks. Refer to Chapters 
11 and 12 for more information on Undistribute files. 


Managing Mail 


F-PROT Professional supports communication between users and administrator in 
the form of bulletins and messages. These are files that are circulated via the 
network shared disk. 


Bulletins are general messages that administrator sends simultaneously to all the 
users. 


Messages are notes that the users send to the administrator. F-PROT Gatekeeper, 
when it finds a virus on a user workstation, also sends a message to administrator. 
The messages identify the sender and the originating workstation. 


Both messages and bulletins are transferred over the network by being copied to 
the appropriate F-PROT Professional directory on the server disk. When F-PROT is 
run on the administration workstation, any new messages that appear in the 
shared MESSAGES directory are copied to the local MESSAGES directory and added 
to the Message List. Likewise, F-PROT Professional run in User mode copies 
bulletins from the shared BULLETIN directory to the local BULLETIN directory and 
appends them to the local Bulletin List. 


1 Sending Bulletins to Users 


Before you can send a bulletin, you must first create it. Since a bulletin is simply a 
file sent through the network, you can write, draw or compile the bulletin file with 
any text editor or other application you want. Users must have the same 
application available in order to read the bulletin. 


To send a bulletin to users, choose Manage Bulletins from the Administration 
menu. This will open the Manage Bulletins dialog box, which contains options for 
editing and deleting old bulletins and creating new ones. The bulletins are 
distributed and undistributed from this dialog. 


To create a new bulletin, click New to open the Bulletin Attributes dialog box 
where you can define the bulletin. 
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In this dialog box, first name the bulletin. F-PROT Professional will thereafter 
recognize the bulletin by that name, regardless of its original file name. 


The next step is to enter the actual name and directory path of the bulletin file. If 
necessary, use the Browse button to locate the bulletin file. 


After you have defined the bulletin in this dialog box, click OK to return to the 
Manage Bulletins dialog. The new bulletin will be on the list, and you can send it 
to users by selecting it on the list and clicking Distribute. 


You can also remove a bulletin from circulation by selecting it on the Bulletin list 
and clicking Undistribute. This makes F-PROT Professional send the Undistribute 
file to the shared disk. The Undistribute file has the same name as the 
corresponding bulletin, but has the extension .del. When F-PROT programs on local 
workstations find the Undistribute file in the shared BULLETIN directory, the 
corresponding bulletin from the local BULLETIN directory is deleted. 


Bulletins can be edited by clicking Edit in the Manage Bulletins dialog box. 
Bulletins can be converted into Write format for editing. 


2 Reading Messages 


Read the user messages by choosing View User Messages from the 
Administration menu. In the dialog box, choose the message from the list. By 
default, the first unread message will be opened and marked as read. 


The dialog box identifies the sender and displays the subject of the message. The 
message text is displayed in the lower portion of the dialog box. 
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The Read Messages dialog box contains the following buttons: 
e Next, to select the next unread message and display its contents; 
e Delete, to remove the currently selected message; 
¢ Delete All, to delete all the messages; 
e Close, to exit the dialog box; and 
¢ Help, to access the context-sensitive Help. 


Reports And Infected Files 


Use the Network Preferences to set up the actions to be taken by F-PROT 
Professional when it discovers a virus on a user workstation. Here you can select 
whether or not the task reports and any infected or suspected files are to be sent to 


administrator. 
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When the Inform Administrator with Results check box is selected and 
incorporated into the users’ versions of F-PROT Professional, a task results report is 
sent to administrator whenever a virus is found during a scan execution. Whenever 
F-PROT Gatekeeper finds a virus, it sends corresponding message to administrator. 
The messages can be read by choosing View User Messages from the 
Administration menu. 


When the Send Infected Files to Administrator check box is selected and 
incorporated into the users’ versions of F-PROT, infected and suspected files are 
automatically sent to administrator. The files are transferred to the INFECT and 
SUSPECT directories, respectively, and the reports go to the REPORTS directory. 
See Chapters 11 and 12 for more information on these directories. 


You can also have the results of some specific task sent to you by selecting the 
option Force Report at First Scan in the Distribute Selected Task dialog box. 
Selecting this option makes the receiving workstations send results of the 
distributed task to administration workstation. 
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The administrator’s F-Agent watches for new messages and reports from users. 
When new messages arrive, the administrator is asked whether F-PROT 
Professional should be started to view the messages. 


Warning If you want to test the performance of F-PROT Professional by scanning a 
large number of files infected with different viruses, be sure to switch this option 
off. Otherwise, every infected file will be copied to the INFECT directory. This 
operation will consume a vast amount of time and disk space. 


1 Viewing User Reports 


Reports can be browsed by choosing View User Reports from the 
Administration menu. This opens the Read Reports dialog box, in which the 
user reports are listed. 


The reports list is similar to the log file. Each report is represented by one line 
which contains the originating workstation ID, the name of the task, the time of 
execution, and the report status. 
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The dialog box contains the following buttons: 


Read, to access a selected report; 

Delete, to remove a report from the report list and the local hard disk; 
Delete All, to remove all reports from the report list and the local hard disk; 
Help, to access context-sensitive Help; and 

Close, to exit the dialog box. 


The actual report can be inspected by either double-clicking on the corresponding 
entry in the Report list, or by selecting the entry from the list and clicking the Read 
button on the lower pane of the dialog box. The report is displayed in a separate 
window. 
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2 Infected and Suspected Files 


F-PROT recognizes two types of ‘at risk’ files: infected and suspected ones. Infected 
files are those files in which the program has detected a recognized virus infection. 
Suspected files are those files that F-PROT Professional determines to may have a 
virus infection. When a file of either kind is sent from a local workstation to the 
network server, it is encrypted and renamed to prevent the infecting virus from 
spreading as a result of unintentional execution of the file. When the file is moved 
to the administration workstation, it is decrypted but does not revert to its original 
name. 


Each infected or suspected file is accompanied by the information file, which 
contains the original name of the file, the directory path for the workstation on 
which it was found, the name of the infecting virus, and the ID of the local 
workstation. 


The infected files can be viewed by choosing View User Infected Files from the 
Administration menu. F-PROT displays the list of infected files, giving the name of 
the virus, the name of the infected workstation, and the name of the infected file 
on the local workstation, complete with the directory path. Below the list, the 
program displays the current file name and location of the file on the 
administration workstation. 


IMPORTANT If the program reports an unknown virus or a new variant of a known 
virus, please contact Data Fellows or your local distributor. 


